HNHacker News
TopNewBestAskShowJobs

joebasirico

107 karma · joined January 14, 2009

submissionscomments
joebasirico··on [dead]
Are there other techniques or topics you think I missed? If so, please add them here to help people.

The purpose of the article is to help people who have been laid off to present themselves as well as possible and to find a new job.

Even though this information may not be completely new, I do still see a lot of the same mistakes being made, both in the applicants we see and the comments I read online. Sometimes just being reminded by a Hiring Manager and a Recruiter that these things really do matter can help.

joebasirico··on [dead]
Correct, that's my comment. When you submit a link to HN you it asks for a URL, Title, and Text. The text is automatically added to the posting as a comment.
joebasirico··on [dead]
This article dives deep to help you create the ideal resume, find a new position, do company research, set yourself apart from all the other applicants, and how to nail your interviews and get an offer.
joebasirico··on Ask HN: Who is hiring? (January 2022)
Highspot | Senior/Principal Security Engineers | Remote USA/Canada | Full-time

The Highspot Security Team is hiring Security Engineers for ProdSec, AppSec, and CorpSec. We’re building a team that has all the best aspects of an agile consulting team (research, speaking and attending conferences, building tools, and delivering real results) with the best things of working at a well funded, rapidly growing, startup (funding, time to get things done and see your efforts make an impact).

We’re tackling fun challenges with great support and investment in our projects. If you want to learn more please reach out to me directly or apply with one of the links below.

Principal Security Engineer - Remote: https://jobs.lever.co/highspot/d8b57286-1395-4bf5-81b3-fbcfb...

Senior Security Engineer - Remote: https://jobs.lever.co/highspot/d1f8016d-e2c8-448b-97a6-11cc6...

Senior CorpSec Security Engineer: https://jobs.lever.co/highspot/86598c91-c701-4c93-8d93-9a5a7...

joebasirico··on Ask HN: Who is hiring? (July 2021)
Highspot is hiring Principal, Senior, and Security Engineers

Location: Seattle, WA. Remote Possible

We're hiring Security Engineers at all levels for our Product Security team at Highspot.

Highspot is a rapidly growing Pre-IPO startup that recently achieved "Unicorn" status in Seattle. We're building security solutions for our platform today with an eye on the company that we will be as we double every year.

Highspot may be growing quickly, but we haven’t lost our inclusive, respectful, and team focused culture. We’re looking for passionate people from all backgrounds who want to learn everything they can. Our team supports each other to achieve our best work. We leave the team and company competition or try harder thinking at the door.

We encourage our team to build tools, speak at and attend conferences, and publish research. We heavily use and rely on Open Source tools and software and we want to build and contribute back to those tools and to develop new techniques to help our security industry grow and improve together.

If this sounds exciting to you and you’re interested in learning more about our team and what it takes to be part of an exceptional, passionate, technical security engineering team, please reach out. We use tools to make our lives easier, make us more effective, and to help us get better security coverage quickly, but manual assessment and vulnerability hunting is where we will make the most impact.

Whether you're a seasoned pro or relatively new to security I encourage you to check out Highspot. Our tech stack is fun (React, Ruby, Clojure) and modern (AI/ML, interesting and complex systems) and we service millions of users and are growing super-fast.

You'll find more information on the specific job postings. We're also hiring a ton of other positions that you can find on our Careers page: https://www.highspot.com/careers/

*Security Engineer* - https://jobs.lever.co/highspot/2c36c5b2-feee-48f5-aed2-80fd3...

*Senior Security Engineer* - https://jobs.lever.co/highspot/d1f8016d-e2c8-448b-97a6-11cc6...

*Principal Security Engineer* - https://jobs.lever.co/highspot/d8b57286-1395-4bf5-81b3-fbcfb...

joebasirico··on Ask HN: Who is hiring? (March 2021)
Highspot | (Senior) Security Engineer (and more!) | Seattle, WA

I'm hiring Security Engineers for my Product Security team, but there are many other incredible positions open at Highspot. Check out the Careers page for more info: https://www.highspot.com/careers/

Are you looking to join a rapidly growing team of security professionals in order to build an industry leading and bleeding edge security team?

Highspot may be growing quickly, but we haven’t lost our inclusive, respectful, and team focused culture. We’re looking for passionate people from all backgrounds who want to learn everything they can. Our team supports each other to achieve our best work leaving the intra-team or intra-company competition or try harder ethos at the door.

We encourage our team to build tools, speak at and attend conferences, and publish research. We heavily use and rely on Open Source tools and software and we want to build and contribute back to those tools and to develop new techniques to help our security industry grow and improve together.

If this sounds exciting to you and you’re interested in learning more about our team and what it takes to be part of an exceptional, passionate, technical security engineering team, please reach out.

We use tools to make our lives easier, make us more effective, and to help us get better security coverage quickly. We understand tools can make us better, but manual assessment and vulnerability hunting is where we will make the most impact.

Whether you're a seasoned pro or relatively new to security I encourage you to check out Highspot. Our tech stack is fun and modern and we service millions of users and are growing really fast.

* Security Engineer - https://jobs.lever.co/highspot/2c36c5b2-feee-48f5-aed2-80fd3...

* Senior Security Engineer - https://jobs.lever.co/highspot/d1f8016d-e2c8-448b-97a6-11cc6...

joebasirico··on Changes to LastPass Free
I recently migrated from LastPass to 1Password. Honestly it's been great. The UI is better, sharing vaults is easier, they have integrations with haveibeenpwned.com, and integrations are seamless. There's no free tier, but the cost feels worth it to me. I was able to get my whole family on 1Password without too much hassle.
joebasirico··on Facebook Q3 2020
This slide deck makes me really uncomfortable.

1.8 Billion Active Users on Facebook in Q3 of 2020

Every user in the US brings gives Facebook about $40 in advertising revenue every quarter

Facebook made $21 BILLION dollars in advertising, just in Q3 of 2020

Facebook has an effective tax rate of between 4% (in Q3 of 2020) and 20% in Q4 of 2019.

You’re worth a bit less than $160/year to Facebook in advertising revenue. They made 70 Billion dollars last year, and have made almost 60B this year already (82% of what they made in 19). They are taxed in the low double digits.

My questions to you: - Did you get $160 worth of value out of Facebook? - What’s your annual tax rate?

My guess is it’s No to the first question and a lot more than 4% to the second.

joebasirico··on Emergency Preparedness During Coronavirus Frenzy
Thanks for reading my article. I agree this is overkill for this specific Coronavirus outbreak. The point of my article, though, was to show that with little outlay you can prepare yourself for a wide range of risks. In a city I think it’s important to prepare yourself for being able to stay in one place, without external resources, for some time, how much time is entirely up to you.

I see a lot of people here panicking and buying up all the toilet paper and hand sanitizer because they have never thought of this before. It’s best to be prepared, or at least thoughtful about your approach.

joebasirico··on Deconstructing a Sexploitation Attack
Absolutely, I should have made this clearer in the article. There have been many breaches in the past and the more places you put your sensitive data the more likely it is to be lost!
joebasirico··on Deconstructing a Sexploitation Attack
Yea, I'm glad it turned out to be nothing. I was pretty concerned to see my valid credentials in the subject line. The PDF was reasonably convincing, and very threatening. It got me thinking about things like "this can't be real, right? but what if it is? Should I just pay it to make it go away?" I figured if I was thinking those thoughts others might, so it was worth the investigation. Thanks for reading!!
joebasirico··on Dark Mode for Slack
I use the Hoth theme in Slack and through it was pretty cute that they change the name of that theme to Dagobah in dark mode.
joebasirico··on LogMeIn acquires Lastpass
My company uses join.me (a Logmein product) all the time for easy screen sharing. It's one of the few quick screen sharing apps out there that doesn't require a heavy download and is user friendly enough to be used by all of the people in our company and all of our client.

I've been using LastPass since 2011 and have been really happy with it (other than the slightly opaque UI and design from the 90's).

I'm hopeful about the acquisition, maybe logmein can give some UI/UX guidance to the LastPass team, while the LastPass team can help expand and grow to help more people to use a password manager.

If not, there are plenty of other password managers out there, I suppose.

joebasirico··on Scroll Slow. Have Fun
My son just got one of those types of books for Christmas. In the states there is a run of them called "Scanimation" books.

http://www.amazon.com/s/url=field-keywords=scanimation

joebasirico··on ChromaShift: Browser-based game written in ClojureScript
Cool game, and really nice work in 48 hours!

I realize security probably not on the top of your feature list in 48 hours, but since I work for a security company doing security assessments it's is one of the first things I think about. I noticed an issue that will let me win without racing.

The reason I bring this up is not, in any way, to diminish your work, but to highlight that you don't get much security for free in these types of frameworks. So this isn't a big deal for this game, but in case somebody was using this for a more sensitive project they may want to be careful.

joebasirico··on Ask HN: Who is Hiring? (April 2012)
Boston, MA

Security Innovation is hiring two roles.

A Security Engineer and a Lead Security Manager. If you eat, sleep and breathe Software Security please apply! We've also setup a challenge website for you to test your skills on at: http://bit.ly/Hekjxe (email jobs@securityinnovation.com for hints if you get stuck).

Lead Security Manager

Our Lead Security Manager will be tasked with delivering security assessments and managing a team of security engineers to deliver security assessments for Security Innovation's wide array of clients; from web, embedded, desktop, mobile and cloud based applications. This person should have some management experience and deep technical, security experience. Their day to day tasks include helping to scope application security projects, delivering the projects, leading and growing a team of security engineers and helping the local sales and marketing resources with proper messaging and understanding. Additionally this person will be expected to lead projects and interface directly with our clients. This person should have at least 3-5 years of manual application penetration testing experience, deep security knowledge, and 1-2 years of development experience.

Security Engineer

At Security Innovation Security Engineers are tasked with delivering security assessments for our wide array of clients on an even wider array of technologies and platforms. This person should have deep technical and security knowledge. This person will be tasked with performing manual Penetration Tests, Code Reviews, creating Threat Models, Design Reviews and more. Beyond their technical skill this person should have strong written and spoken communication skills. Additionally, this person should have 1-3 years of manual application assessment experience, deep security experience, and development experience would be a plus.

About Security Innovation

Security Innovation helps our clients to reduce their overall risk by providing application security services, education and standards. We assess the security of a wide range of applications and technologies to ensure they properly protect their sensitive data. Security Innovation is headquartered in Boston and has a branch office in Seattle, WA. This is an immensely challenging and rewarding company to work for, we have built a tight knit team of security experts who are well regarded as leaders in the field. As a reward for being the best in the industry we provide our engineers with 10% of their time for research, hefty hardware and research budgets, retirement, compensation and insurance packages. Oh, and we have unlimited vacation too.

More info at: http://bit.ly/pisNHF

joebasirico··on Ask HN: Who is Hiring? (October 2011)
Seattle, WA & Boston, MA

Be a part of an awesome team of hackers with Security Innovation.

We find security issues in some incredibly interesting pieces of software, from web applications to embedded and mobile to desktop and server apps. If you think the world is a scary, insecure place and 0x41414141 makes you smile, please apply!

We encourage you to do your own security research and give you time and budget to pursue those topics. We want you to attend and speak at the conferences, write tools, white papers and blog posts on topics of your choosing. Beyond that we have an awesome perks package. You get a ton of freedom to be a rockstar.

We have developed or helped develop Blackmamba(http://rootfoo.org/blackmamba), Firesheep and other cool security tools.

We have four positions (and multiple openings) open:

- Security Engineer - the pen-testers that find vulns

- Lead Security Engineer - a seasoned security professional that can run our new Boston based security team

- Sales Engineer - a technical engineer that can help bridge the gap between sales and the engineers

- Linux System Engineer - Help build and design the most secure Kiosk system in the world based on some really cool tech.

If this sounds up your alley, e-mail me at jobs@securityinnovation.com or find out more about us at http://bit.ly/SICareers

joebasirico··on Learn about security from free online training
Hey, submitter of the above link here. I had a hard time coming up with a non-spammy sounding title for this submission, but my company, Security Innovation, does a lot of application security work and has created some very cool eLearning.

If you're interested in learning about security this is a great (free) place to start. There are six courses that will be given away for free. I encourage you to check them out.

joebasirico··on Ask HN: Who is Hiring? (July 2011)
If the candidate is smart, passionate and very excited about security we would absolutely hire a fresh graduate. We can also sponsor an H1B.
joebasirico··on Ask HN: Who is Hiring? (July 2011)
Security Innovation's (http://securityinnovation.com) team of amazing hackers is hiring (Boston, MA).

I'm looking to hire a couple awesome security professionals for our Boston office. We assess a wide range of really interesting technologies, from web apps to mobile to crypto. You have to have a true passion for security, most of the team does this on their off time and it's all we talk about. If you dream in hex, clickjack for breakfast, exploit XSS, SQLi and CSRF for lunch, Buffer Overflows and Format String Vulns for Dinner and some AuthN/AuthZ hijacking for a midnight snack you're our kind of candidate.

You'll have time and budget to do research, go to and speak at conferences, and build tools that will change the internet (We helped develop Firesheep, if you remember that).

You can e-mail me directly: jbasirico at securityinnovation dot com for more informaiton.

Check out our postings http://securityinnovation.recruiterbox.com/ http://www.linkedin.com/jobs?viewJob=&jobId=1718329 http://www.linkedin.com/jobs?viewJob=&jobId=1718256

joebasirico··on YouTube is going Live
I'm sure there is a market for this, but it's not me or my demographic. Technical hurdles aside, I tend to trend away from most "live" events. I like the idea of live breaking news. For most things, however I'd rather have them on demand. This is one of the reasons why my wife and I recently canceled cable for Hulu, Netflix and other on demand services.

I don't see myself structuring my day around "Wheezy Live On Youtube"

joebasirico··on Ask HN: Who Is Hiring? (October 2010 Edition)
Seattle, WA

Security Innovation is hiring some great Software Security Engineers. We help our customers find security issues before for they ship by reviewing code, finding vulnerabilities in their software manually, writing tools, reverse engineering, and analyzing their architecture and design. We get to work on all kinds of different projects: Web, Mobile, Firmware, Desktop Apps, and much more.

We're looking for a couple of great engineers to start soon. The ideal candidate would posses strong development skills, both in standard application development languages (C/C++, Java, C#, etc.) and a scripting language (python, perl, ruby, etc.) They'd also be passionate and knowledgeable about existing security vulnerabilities, attacks and threats (XSS, SQL injection, Buffer Overflows, CSRF, etc.).

Security Innovation is a really cool place to work, we're constantly challenged to learn new things and given the opportunity to grow. (Annual Conference budget, Take Friday afternoons off to work on professional development projects, and lots more). Our open layout office is located just two blocks away from Pike Place Market.

If this sounds like something you'd be interested in, please drop me a line with your resume. (jbasirico@securityinnovation.com - please put "hacker news job posting" in the subject line) or check out our "official" job posting at http://securityinnovation.com/company/careers/job-security-e...

joebasirico··on Facebook Down, Like Buttons Vanish, Internet Implodes
When I heard FB was down I went over to twitter to see how many tweets this was generating, I was surprised to see the first refresh of "XXXX more tweets since you started searching."

I decided to start keeping track and I made a graph of the difference between refreshes. You can see my graph here. It seems like in the course of just a few minutes (I was probably conducting my little experiment for 10 min?) you can see the frenzy gaining momentum then it seems to die down until only hundreds of people are talking about it per 15 second refresh.

A little bit about the graph, each tick mark on the bottom represents a refresh (15 seconds or so I think). The Y axis is the difference between refreshes.

Graph: http://drp.ly/e3oH

joebasirico··on Ask HN: Who's Hiring?
Security Innovation in Seattle, WA is hiring.

We're a Software Security Company looking for great Security Engineers. I'm the Director of Security Services at Security Innovation, so if you have any questions e-mail me at jobs@securityinnovation.com

Here's a link to the formal job description: http://securityinnovation.com/company/careers/job-security-e...

Here's our "informal" job description: Are you passionate about software security? Do you look at MD5 and RC2 with disgust? Do you find yourself reciting hexadecimal often... in little endian order? Do you find security issues everywhere you look? Do you often wonder how software security can be so broken, and why more people don't understand how SQLi, XSS, and CSRF work? Do you smile uncontrollably when you see 0x41414141 on the stack? Would you rather stay up all night, for 12 hours strait, writing a tool to automate a task than do something repetitive and boring for an hour?

If so, then I have great news for you - Security Innovation is hiring! We're looking for somebody who will fit in with our current team of extremely talented security engineers. We pay well, have great benefits, and provide a budget for annual security conferences. We have an awesome office downtown and get to travel occasionally. Enjoy the challenge of penetration testing n-Tier applications, crypto systems, and web apps from some of the largest software vendors in the world while enjoying the office lifestyle of a small, yet established, company.

If this sounds like the opportunity you have been searching for, then look no further, email us your resume today!

joebasirico··on Proposal: "{" and "}" to be known as openstache, closestache
I think of the way the slash would fall if it were a pen on a desk. The forward slash would fall forward / -> the back slash would fall back \ <-
joebasirico··on A wedding gift for our co-founder became our startup's newest product.
I was recently married (this summer) and I can say that I would have loved to have something like this at my wedding. I lugged my laptop and large screen monitor to the wedding and set it up on a side table to display a slide show of me and my (future) wife growing up. It was something that people really got a kick out of.

It’s really not that difficult to haul a laptop to a wedding, there’s so much to setup already it’d be a drop in the bucket. Also, I had one of my best men (they were all best men) in charge of the slideshow, I think another one of them could have been in charge of the video laptop. I think having a MacBook is the major barrier to entry here.

I realize I’m probably slightly more technically savvy than the average groom, but I honestly got excited when I saw this and thought “Man! Where was this when I got married?”

joebasirico··on Life Below 600px
Perhaps I'm missing the concept of "the fold" the author is trying to get across, but I think 37Signals is a really good example of putting things _above the fold. Looking at their site they even have a line at the fold separating the two sections. I think they've done used the concept of "the fold" really well, don't get me wrong, but it's absolutely there.

The black section at the bottom I always just assumed was a footer, not a call to action, and honestly never read that before.

Ironically it seems to me the news sites seem to have done away with the concept of the fold the best. http://www.bbc.co.uk/, http://www.nytimes.com/, http://seattletimes.com

joebasirico··on Google Chrome for Mac released (beta)
I've been using chromium for a while now and have been fairly happy with it (other than a bit of scrolling performance and some flash funnyness). Has anybody done a side by side comparison of Chromium and Google Chrome on the Mac?

The UI looks identical, functionally they look very similar, and performance seems about the same as well.

Thoughts?

joebasirico··on Working without distraction : my minimalist Macintosh experience
Agreed, I recently installed isolator for the mac. I love it when it's on, but a lot of the time I need to switch between two or more windows. My IDE and reference document and browser; Word and Excel.

I've found it's really great for braindump type tasks where I need to write or code something quickly.

joebasirico··on White roofs catch on to save energy costs
I don't mean to make fun, but this sentence struck me as funny: "Relying on the centuries-old principle that white objects absorb less heat than dark ones"

As if before those "centuries" light and dark objects absorbed heat differently. :)

Page 1 of 2Next →